Why Does Search Engine Poisoning Spread Malware?

706 views
β€’
March 25, 2012
by
RSAC Cybersecurity
YouTube video player
Why Does Search Engine Poisoning Spread Malware?

TL;DR

Search engine poisoning succeeds because search services attract many potential victims who arrive intending to click unfamiliar links and generally trust the results. Attackers exploit indexing by showing a search crawler one page, then delivering different content to users, while heavy legitimate and malicious search optimization creates clutter that makes poisoned results difficult to identify.

Transcript

Thank you. Thank you for the chance to be here and present this, uh, short, condensed version of my RSA presentation on search engine poisoning. I'm Chris Larsen. I'm the malware research team lead with Blue Coat Systems. And two years ago, I came to RSA and did a presentation on search engine poisoning, and at that point, I felt like I'd covered t... Read More

Key Insights

  • Search engine poisoning remains effective because search engines combine enormous visitor volume with users who are specifically prepared to click unfamiliar destinations. Users also tend to trust that search providers have removed dangerous material, increasing the opportunity for a poisoned result to attract a victim.
  • Search indexing creates built-in attackability because a malicious operator can supply one page to the crawler and different content to the eventual visitor. The search engine effectively returns the attacker's URL to a user, who then enters an environment controlled by the attacker.
  • Search optimization activity creates a large haystack in which poisoned pages can hide. Legitimate publishers and attackers both compete for placement among the leading results, so search providers must distinguish malicious manipulation from a vast amount of ordinary promotional and linking activity.
  • Older poisoning operations used large groups of websites containing thousands of bogus pages. The pages covered many possible search terms, linked to one another to appear valuable, and received aggressively spammed inbound links that encouraged search engines to discover and index them.
  • Image search presents distinctive filtering difficulties because computers handle and parse large volumes of text more effectively than pictures. Detecting suspicious image results can require contextual or cultural understanding, such as recognizing that anime imagery is unlikely to belong naturally on an unrelated hip-hop blog.
  • Attack-vector analysis works by tracing a malware delivery chain backward from the site serving the malicious payload. Following the referring sites through several steps commonly reaches a trusted service, allowing researchers to categorize the attack's origin as search, webmail, social networking, or another channel.
  • Blue Coat's mid-year attack-vector chart showed search engine poisoning producing more attacks than all the other displayed vectors combined. That finding challenged the researchers' earlier impression that search providers were winning simply because searches filled with numerous obvious malicious links had become harder to reproduce.
  • Search filtering performance varies by provider and language according to the presented research. Bing had caught up with Google, while Baidu and Yandex remained substantially more dangerous and still admitted older poisoning techniques. Google Hong Kong and Google Russia outperformed native-language competitors but performed slightly worse than English-language Google.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: Why is search engine poisoning an effective malware vector?

Search engine poisoning is effective because search services attract very large numbers of potential victims. Visitors arrive precisely because they do not know which site contains the information they want, so they are prepared to click unfamiliar links. They also trust the search provider to exclude dangerous material, while attackers can exploit the indexing process to place malicious destinations among apparently legitimate results.

Q: How does search engine poisoning manipulate search results?

Search engine poisoning works by giving a search crawler a page designed to be indexed and ranked. When the search engine later returns that page's URL to a user, the user visits a site controlled by the attacker. The attacker can then deliver content entirely different from what the crawler received, turning the normal indexing and referral process into part of the attack chain.

Q: Why is poisoned content difficult for search engines to detect?

Poisoned content is difficult to detect because it sits within a huge amount of search optimization activity. Legitimate publishers and malicious operators alike want their pages among the leading results, creating substantial clutter. Attackers can also present crawlers with content different from what users receive, so the search engine's inspection does not necessarily reveal the page ultimately delivered to a visitor.

Q: How did older search engine poisoning campaigns gain visibility?

Older campaigns created large collections of websites hosting thousands of bogus pages. This scale allowed attackers to target a broad range of possible search terms. The pages could link to one another to persuade Google or Bing that they were valuable, while attackers also spammed links across the web to encourage discovery, indexing, and stronger apparent relevance.

Q: Why can image search poisoning be harder to identify?

Image search poisoning can be harder to identify because search systems are better at indexing and parsing large volumes of text than interpreting pictures. Suspicious images may only become apparent through contextual or cultural knowledge. In the example presented, anime-related eye images appeared on a hip-hop blog, a mismatch that a person could question but a computer might not understand.

Q: How did Blue Coat determine where malware attacks began?

Blue Coat began with the site actually serving malware and examined which site had directed the user there. Researchers then followed the referral path backward through the chain of sites. After three or four steps, they would usually reach a familiar, trusted service. That starting point allowed the attack to be classified as originating from search, webmail, social networking, or another vector.

Q: How did major search engines compare at filtering poisoned links?

The research found that Bing had caught up with Google, whereas Google had been measurably safer two years earlier. Baidu and Yandex remained much more dangerous and continued to be fooled by older poisoning methods that no longer fooled Google and Bing. Google Hong Kong and Google Russia performed better than their native-language competitors, though slightly worse than English-language Google.

Q: Why were non-English search results more exposed to poisoning?

Non-English content was more exposed because the algorithms used to screen out junk sites were described as less mature, or potentially absent, outside English. This pattern appeared across search engines from different languages and countries, as well as within Google and Bing. Google’s foreign-language services still outperformed Baidu and Yandex in the comparisons discussed, but trailed google.com slightly.

Summary & Key Takeaways

  • Search engines are attractive malware entry points because they receive enormous traffic and serve users who do not yet know where their desired information resides. Those users expect to explore unfamiliar results, and their trust in the search provider can make a malicious link appear safer than it actually is.

  • Search engine poisoning exploits the separation between indexing and user visits. An attacker can present an apparently relevant page to a search crawler, obtain placement for its URL, and later show a visitor different content. Extensive legitimate and malicious optimization activity provides additional cover by creating a large, noisy field of competing pages.

  • Blue Coat traced attacks backward from malware-serving sites through chains of intermediary sites until reaching familiar starting points such as search engines, webmail, or social networks. Its mid-year data showed search engine poisoning exceeding all other measured attack vectors combined, even though obvious clusters of dangerous results had become harder to find.


Read in Other Languages (beta)

Share This Summary πŸ“š

Explore More Summaries from RSAC Cybersecurity πŸ“š